CVE-2022-26143

CRITICAL(9.8)KEVLikely Exploited

MiCollab, MiVoice Business Express Access Control Vulnerability

Description

CVE-2022-26143 is an unauthorized access vulnerability in Mitel MiCollab and MiVoice Business Express systems that enables attackers to leverage the TP-240 driver as a DDoS amplification vector. The flaw allows an unauthenticated attacker to send specially crafted UDP packets to the TP-240 service, which responds with massively amplified traffic directed at a target of the attacker's choosing. With an EPSS score of 76.7% (98.9th percentile), this vulnerability has been extensively exploited for DDoS amplification attacks. CISA has added CVE-2022-26143 to the Known Exploited Vulnerabilities catalog.

KEV Information

Vendor
Mitel
Product
MiCollab, MiVoice Business Express
Date Added
March 25, 2022
Due Date
April 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
mitelmicollab< 9.4; 9.4
mitelmivoice business express<= 8.1

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-284: Improper Access Control

CVE-2022-26143 results from improper access control in the TP-240 driver used by Mitel MiCollab and MiVoice Business Express. The service accepts and processes commands from unauthenticated external sources without proper authorization checks, allowing an attacker to abuse the system's test functionality to generate amplified network traffic for DDoS attacks.

Learn more: CWE-284 — Improper Access Control

Impact Analysis

CVE-2022-26143 poses a severe threat not only to the vulnerable Mitel systems themselves but to the broader internet, as it enables DDoS amplification with an amplification ratio of approximately 4.3 billion to 1. A single small UDP packet can generate a massive volume of traffic directed at a victim, making this one of the most potent DDoS amplification vectors ever discovered. The EPSS score of 76.7% (98.9th percentile) reflects the widespread abuse of this vulnerability by DDoS-for-hire services and threat actors. CISA's inclusion in the KEV catalog confirms active exploitation. The vulnerability impacts both the availability of the Mitel systems being abused and the targets of the amplified DDoS attacks.

Exploit Maturity

CVE-2022-26143 has been extensively exploited for DDoS amplification attacks since its discovery. Security researchers documented the vulnerability being actively abused to launch terabit-scale DDoS attacks. CISA confirmed exploitation by adding it to the KEV catalog. The vulnerability requires no authentication and minimal technical expertise to exploit, making it accessible to DDoS-for-hire services. The EPSS score of 76.7% (98.9th percentile) reflects the massive exploitation activity targeting exposed Mitel systems.

Remediation

  1. Apply Mitel security patches that address CVE-2022-26143 as recommended in Mitel's security advisory. Update MiCollab and MiVoice Business Express to the latest patched versions.
  2. Block external access to the TP-240 service (UDP port 10074) at the network perimeter. This service should never be accessible from the internet.
  3. Implement network access control lists (ACLs) to restrict TP-240 traffic to only trusted internal networks where it is required for legitimate functionality.
  4. Monitor for unusual outbound traffic volumes from Mitel systems, which could indicate that the system is being abused as a DDoS amplification reflector.
  5. Conduct an audit of all Mitel deployments to ensure that no instances have their TP-240 service exposed to the internet, and implement ongoing monitoring to detect any configuration drift.

Technical Details

CVE-2022-26143 exploits an improper access control weakness (CWE-284) in the TP-240 driver used by Mitel MiCollab and MiVoice Business Express systems. The TP-240 driver exposes a UDP service (typically on port 10074) that is intended for system testing and diagnostics. Due to insufficient access controls, this service accepts commands from any source without authentication. An attacker can send a small specially crafted UDP packet containing a test command that instructs the TP-240 driver to generate a large volume of response traffic directed at an arbitrary target IP address. The amplification ratio can reach approximately 4.3 billion to 1, meaning a single small packet can trigger gigabytes of response data. This makes it one of the most powerful DDoS amplification vectors ever discovered, capable of generating terabit-scale attacks from a small number of vulnerable systems.

Frequently Asked Questions

Is CVE-2022-26143 being actively exploited?

Yes, CVE-2022-26143 has been extensively exploited for DDoS amplification attacks. CISA confirmed active exploitation by adding it to the KEV catalog. The vulnerability has been abused by DDoS-for-hire services to launch terabit-scale attacks.

What products are affected by CVE-2022-26143?

Mitel MiCollab and MiVoice Business Express systems with the TP-240 driver are affected. Any deployment where the TP-240 service is accessible from the network is potentially vulnerable to being abused as a DDoS reflector.

How do I fix CVE-2022-26143?

Apply Mitel's security patches and immediately block external access to the TP-240 service (UDP port 10074). Ensure the service is only accessible from trusted internal networks.

How severe is CVE-2022-26143?

CVE-2022-26143 enables DDoS amplification with a ratio of approximately 4.3 billion to 1, making it one of the most potent DDoS amplification vectors ever discovered. The EPSS score of 76.7% reflects massive exploitation activity.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score87.21%
EPSS Percentile99.7%

Dates

PublishedMarch 10, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.